Description
MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/.
References (5)
Core 5
Core References
Vendor Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.html
Various Sources mailing-list
x_refsource_mlist
http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html
Vendor Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47678
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33349
Scores
EPSS
0.0043
EPSS Percentile
63.0%
Details
CWE
CWE-264
Status
published
Products (10)
mediawiki/mediawiki
1.11 (2 CPE variants)
mediawiki/mediawiki
1.11.1
mediawiki/mediawiki
1.11.2
mediawiki/mediawiki
1.12.0 (2 CPE variants)
mediawiki/mediawiki
1.12.1
mediawiki/mediawiki
1.12.2
mediawiki/mediawiki
1.12.3
mediawiki/mediawiki
1.13.0 (3 CPE variants)
mediawiki/mediawiki
1.13.1
mediawiki/mediawiki
1.13.2
Published
Dec 19, 2008
Tracked Since
Feb 18, 2026